MetaMask Browser (on Android) does not enforce Content-Security-Policy heade

Smart devices software vulnerabilities
Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

MetaMask Browser (on Android) does not enforce Content-Security-Policy heade

Post by Shane1145 »

@renniepak discovered an issue with the MetaMask Mobile browser where it ignored content-security-policy headers set by websites. This occurred due to an error in how the application was handling web requests while trying to ensure that the MetaMask JavaScript provider was not blocked after being injected into a webpage. The MetaMask engineering team has since upgraded the MetaMask Browser to address this issue, and eliminated several complexities that would risk a similar issue occurring in the future.


https://hackerone.com/reports/1941767
Post Reply